NVD disclosure day

Published threat advisories for March 9, 2023

CVE advisoryCRITICAL

CVE-2023-27205

Best POS Management System SQL Injection Vulnerability.

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

A SQL injection vulnerability exists in a point-of-sale management system, enabling unauthenticated attackers to potentially access and alter sensitive sales data. This issue impacts systems utilizing the affected software and could have significant implications if exploited. The primary concern is confirming its prese

CVE advisoryCRITICAL

CVE-2023-27204

Best POS Management System SQL Injection Vulnerability

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

A SQL injection vulnerability exists in Best POS Management System 1.0 via the `id` parameter in `manage_user.php`. Attackers can exploit this over the network without authentication to access, modify, or delete sensitive data, potentially impacting system integrity and confidentiality. Confirmation of system usage and

CVE advisoryCRITICAL

CVE-2023-27203

Best POS Management System SQL Injection Vulnerability

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

A SQL injection vulnerability exists in the Best POS Management System, allowing for potential unauthorized access and manipulation of data through its billing component. This flaw, reachable via the 'id' parameter in '/billing/home.php', could impact system and billing data integrity and confidentiality if the softwar

CVE advisoryCRITICAL

CVE-2023-27202

Best POS Management System SQL Injection Vulnerability.

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

A SQL injection vulnerability in Best POS Management System could permit attackers to manipulate database queries via specially crafted web requests. This may result in unauthorized access to, modification of, or deletion of sensitive business and customer data. Organizations using this system should assess its interne